AFC Ajax drops ball as flaws let hackers play admin with tickets and bans
2026-03-27T19:23:53Z•7ea9594afba04182ed7e5926040714da08d859af9035a77ee5b56a66840b22e8
AFC AjaxPII exposureaccess controlaccount compromisedata breachincident responseprivilege escalationstadium securityticketing systemweb application
What happened
AFC Ajax suffered a data breach after attackers exploited vulnerabilities in the club’s internal systems—apparently in ticketing/account management—to gain administrative access. The intruders could manipulate user accounts, modify or lift stadium bans and tamper with tickets, and exposed fan data and internal resources. The incident reflects poor access controls and insecure web-facing systems in a high-profile sports organization.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- 7ea9594afba04182ed7e5926040714da08d859af9035a77ee5b56a66840b22e8
- Enrichment time
- 2026-03-27T19:23:53Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.